Security Risk Management Mount Prospect IL

Security risk is a function of the likelihood of attack, consequence of successful attack, and security system ineffectiveness. To estimate relative security risk, the qualitative estimates for likelihood of attack, system ineffectiveness, and consequence are logically combined.

Local Companies

ANTENAS MEXICO
800-768-0686
287 N 8TH ST
WHEELING, IL
Illinois Protection & Investigation
847-983-4702
7333 N. Harlem Ave.
Niles, IL
American Custom Security
847-387-7181
8819 N. Central
Morton Grove, IL
American Nuwire
(312) 437-8100
1629 W Sherwin Av
Chicago, IL
All Pro Security Systems
(312) 671-7722
5409 1/2 N Clark
Chicago, IL
Universal Security Inc
(312) 642-7447
1640 N Wells
Chicago, IL
Red Spider Security
312-730-5148
311 W Chicago #3
Chicago, IL
Eagle Eye Surveillance Chicago LLC
312-787-7795
213 W. Institute Pl. Ste. #507
Chicago, IL
Protective Solutions
312-266-7233
920 N.Franklin st.
Chicago, IL
Titan Security Services Inc
(312) 902-3400
614 W Monroe
Chicago, IL

Risk Estimation
Security risk is a function of the likelihood of attack, consequence of successful attack, and security system ineffectiveness. To estimate relative security risk, the qualitative estimates for likelihood of attack, system ineffectiveness, and consequence are logically combined. A simple method, based on expert judgment, for combining the three risk parameters to estimate security risk will be discussed. The security risk estimates are relative, not absolute, but they can be used to make risk management decisions. A relative risk level is valuable to:
  • Compare risk levels for a spectrum of malevolent threats
  • Compare risk levels for a spectrum of facilities, industries, or organizations
  • Compare the cost-effectiveness and other impacts of potential improvements

    Comparison of Estimated Risk Levels
    Estimated risk levels are compared to a predetermined risk threshold to decide whether further analysis is required. The threshold is determined by the analysis team and the security risk managers.

    Risk Reduction Strategies
    If the estimated baseline risk level for the threat spectrum is judged to be above the established threshold (too High), risk reduction strategies for the system may be considered. Risk reduction strategies focus on reducing the levels of the parameters of the security risk equation: likelihood of attack, system ineffectiveness, and consequence. In practice, risk reduction is made most successful by improving protection system effectiveness and mitigating consequences. Risk Reduction Upgrades – Security system planners must address how to reduce security risk. Planners might consider adding features to increase physical or cyber-protection system effectiveness and/or to reduce or mitigate consequences. Sitespecific vulnerabilities identified in the system effectiveness analysis provide guidance for adding/modifying features. Upgrades to the system might include retrofits, additional safeguard features, or additional consequence mitigation features. Consequence analysis and system effectiveness analysis should then be repeated for the upgraded system in order to estimate a risk level associated with the upgraded system. If the estimated risk for the upgraded system is below the threshold, the upgrade is completed. If the risk is still above the threshold, the upgrade process should be repeated until the risk level is judged to be below the threshold. Impact Analysis – Once the system upgrade has been determined, it is important to evaluate the impacts of the risk reduction on the mission of the facility and the cost. If system upgrades put a heavy burden on normal operation, a trade-off would have to be considered between risk and operations. Budget can be the driver in implementing security upgrades. A trade-off between risk and total cost may have to be considered. The assessed level of risk and the upgrade impact on cost, mission, and schedule are valuable information to security risk managers.

    PRESENTATION TO MANAGEMENT
    The final step in the risk assessment process is the preparation of a presentation package for the risk managers and stakeholders. The presentation generally includes the threat description, the security risk estimates for the baseline system, descriptions of any risk reduction packages, and the results of the impact analysis for the risk reduction package(s). By using comparison to the baseline risk levels, managers are able to understand what the upgrade package is buying them in risk reduction as well as other potential impacts. The total presentation package provides invaluable information for risk management decision makers.

    RISK MANAGEMENT DECISIONS
    Building owners, stakeholders, and risk managers have the risk assessment information package to help them make difficult security decisions. Most importantly, risk managers must decide on the design basis threat or the threat level to which the security system will be designed.

    INFORMATION PROTECTION
    The risk assessment process provides valuable, detailed information for risk managers; likewise, the information could provide valuable information to any potential adversaries. Because the process begins with basic facts and assumptions and each step builds on previous step(s), allowing the information to get into the wrong hands could provide a roadmap for the malevolent threat. Each step of the process provides security sensitive information:
    1. Facility characterization identifies the security concerns, critical asset(s), and their locations.
    2. Threat analysis ultimately defines the level of protection to which the security system is designed. If the perceived highest threat level is the terrorist, the security system will be designed to be much stronger than if the perceived threat is the vandal.
    3. Consequence analysis prioritizes the assets in terms of criticality or value.
    4. System effectiveness assessment provides possible attack scenarios and documented system weaknesses or vulnerabilities. For these reasons, once the process is applied to a specific facility, the entire analysis package must be protected. Most sites will have to develop the infrastructure for protecting, storing, and sharing the risk assessment package.

    Click Here to Purchase this Book
  • Featured Local Company

    ANTENAS MEXICO

    800-768-0686
    287 N 8TH ST
    WHEELING, IL

    Related Local Event
    PLMA - Private Label Trade Show 2009
    Dates: 11/15/2009 - 11/17/2009
    Location: Donald E Stephens Convention Center
    Rosemont, IL
    View Details

    Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

    Topics:
    Advertising Family Home Services Real Estate Resources
    Business Services Fashion Industrial Goods & Services Retail & Consumer Services
    Career Financial Services Insurance Software
    Cars Food & Beverage Internet Technology
    Computer Hardware Franchise Legal Telecommunications
    Construction Health Miscellaneous Trade Shows
    Education Holidays Nightlife Travel
    Entertainment Home Appliances Online Database Weddings
    Environmental Home Electronics Pets World History